Admin Keys, Phishing, and DNS: The New Front Line of Crypto Security
Crypto losses fell in H1 2026, but attacks reached a record. Learn why admin keys, phishing, DNS, credentials, & governance are becoming critical security risks
In the first half of 2026, roughly $972 million was lost across 207 incidents in the crypto industry, a significant decrease from the previous year but still a substantial sum. The number of incidents more than doubled compared to the same period last year, indicating a shift in the security landscape. The industry's traditional approach, focusing on contract bugs, is no longer the primary threat.
Instead, attacks are becoming more frequent and less profitable, with losses falling while the number of attacks increases. Binance's Chief Security Officer, Jimmy Su, notes that while code security has improved, attackers are now targeting people, credentials, and governance systems surrounding protocols. Immunefi's analysis suggests that around 20% of confirmed vulnerability reports are rated critical, and researchers received $13.45 million for 837 valid bugs in the first half of 2026 alone.
The median hack cost around $219,000, while the mean was $4.7 million. A protocol can pass a flawless code audit but still suffer significant losses due to compromised admin keys. Wallet compromises emerged as the costliest category, accounting for more than $444 million in damages, with an average loss of $13 million per event.
This shift in focus from code to operational control highlights the need for robust security measures encompassing credentials, operations, and infrastructure in the crypto industry.
Written by urgent.news from HackerNoon's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.